Web Hack List

Collected research

XSSing client-side dynamic HTML includes by hiding HTML inside images and more

Argues that sites which fetch a URL fragment by Ajax and drop it into innerHTML are vulnerable even without HTML5 cross-origin requests, because every same-origin file becomes HTML. HTML hidden after a JPEG's end-of-image marker survives and executes when the image is rendered as markup, and poisoned User-Agent strings in server logs give the same effect.

Record

Researcher
lava
Published by
blog.andlabs.org
Topic
XSS

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of lava, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .